Candidate: CVE-2014-1879 PublicDate: 2014-02-20 15:27:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1879 https://github.com/phpmyadmin/phpmyadmin/commit/968d5d5f486820bfa30af046f063b9f23304e14a http://www.phpmyadmin.net/home_page/security/PMASA-2014-1.php Description: Cross-site scripting (XSS) vulnerability in import.php in phpMyAdmin before 4.1.7 allows remote authenticated users to inject arbitrary web script or HTML via a crafted filename in an import action. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_phpmyadmin: upstream: https://github.com/phpmyadmin/phpmyadmin/commit/968d5d5f486820bfa30af046f063b9f23304e14a upstream_phpmyadmin: released (4:4.1.7-1) lucid_phpmyadmin: ignored (reached end-of-life) precise_phpmyadmin: ignored (reached end-of-life) precise/esm_phpmyadmin: DNE (precise was needed) quantal_phpmyadmin: ignored (reached end-of-life) saucy_phpmyadmin: ignored (reached end-of-life) trusty_phpmyadmin: ignored (out of standard support) trusty/esm_phpmyadmin: needed utopic_phpmyadmin: not-affected (4:4.1.12-2) vivid_phpmyadmin: not-affected (4:4.1.12-2) vivid/stable-phone-overlay_phpmyadmin: DNE vivid/ubuntu-core_phpmyadmin: DNE wily_phpmyadmin: not-affected (4:4.1.12-2) xenial_phpmyadmin: not-affected (4:4.1.12-2) yakkety_phpmyadmin: not-affected (4:4.1.12-2) zesty_phpmyadmin: not-affected (4:4.1.12-2) artful_phpmyadmin: not-affected (4:4.1.12-2) bionic_phpmyadmin: not-affected (4:4.1.12-2) cosmic_phpmyadmin: not-affected (4:4.1.12-2) disco_phpmyadmin: not-affected (4:4.1.12-2) eoan_phpmyadmin: DNE focal_phpmyadmin: not-affected (4:4.1.12-2) groovy_phpmyadmin: not-affected (4:4.1.12-2) hirsute_phpmyadmin: not-affected (4:4.1.12-2) impish_phpmyadmin: not-affected (4:4.1.12-2) jammy_phpmyadmin: not-affected (4:4.1.12-2) devel_phpmyadmin: not-affected (4:4.1.12-2)